microscopic-answer-24504
08/05/2022, 1:54 PMfreezing-solstice-24704
08/05/2022, 2:11 PMforward_auth
, nginx subrequest
, etc.) to both Kratos and an API key service, or potentially as an authoriser in Oathkeeper
• Use Ory Hydra’s client credentials
• Create a custom service to handle api keys separately to Kratos
There is also a blog post that touches on how you can use Kong’s api key plugin paired with Oathkeeper and Kratos to add api keys to your auth stack https://www.ory.sh/zero-trust-api-security-ory-tutorial/
A similar configuration to the reverse proxy stuff can be seen in this Ory Summit video too!
This isn’t trivial though, we have gone through much research to come up with a solution that woks for us!
Also worth noting that we use gRPC/gRPC-Web, which I believe isn’t supported by Oathkeeper, so this made things a little more complicated for us!microscopic-forest-58980
08/05/2022, 2:22 PMmicroscopic-forest-58980
08/05/2022, 2:24 PMapi
or some such, and then leave it at that.freezing-solstice-24704
08/05/2022, 2:29 PMmicroscopic-forest-58980
08/05/2022, 2:34 PMfreezing-solstice-24704
08/05/2022, 2:47 PMmicroscopic-forest-58980
08/05/2022, 2:52 PMred-machine-69654
08/05/2022, 7:53 PMfreezing-solstice-24704
08/08/2022, 9:16 AMmicroscopic-forest-58980
08/08/2022, 9:17 AMmagnificent-energy-493